Privacy Policy
Disclaimer:
The Company may update or modify this Privacy Policy from time to time, with notice where required by applicable law. Such updates may be made to reflect changes in applicable laws and regulations, business practices, technology, or organizational requirements. We encourage you to review this Privacy Policy periodically to stay informed about how we collect, use, retain, share, store, and otherwise process your Personal Data.
By continuing to access or use our Platform after any updates to this Privacy Policy become effective, you acknowledge the updated Policy. If you do not agree with any provision of this Privacy Policy, please discontinue your use of the Platform and Service.
Privacy Policy
This Privacy Policy (“Privacy Policy” or “Policy”) explains how Rivergo Automation Private Limited (“Company”, “We”, “Us”, or “Our”) collects, uses, retains, shares, stores, and processes Personal Data in connection with the Service provided by us.
The Company determines the purposes and means of processing your Personal Data and is responsible for handling such data in accordance with applicable privacy and data protection laws.
This Privacy Policy constitutes an agreement between the End-User (“You” or “Data Principal”) and the Company and describes the Company’s privacy practices, including those applicable to its Affiliates, where relevant.
By accessing or using our Service, you acknowledge that you have read and understood this Privacy Policy and consent to the processing of your Personal Data as described herein, where such consent is required under applicable law.
This Policy explains the manner in which your Information, including Personal Data and Sensitive Personal Data where applicable, may be collected, used, retained, disclosed, shared, stored, and otherwise processed by the Company.
If you do not agree with the terms of this Privacy Policy, please discontinue your use of our Service.
This Privacy Policy forms an integral part of our Terms of Service and should be read together with our End-User Agreement, which contains additional terms governing your use of the Service.
Capitalized terms used in this Privacy Policy and not otherwise defined herein shall have the meanings assigned to them in the End-User Agreement or under applicable law, including the Digital Personal Data Protection Act, 2023 and the rules made thereunder, as applicable.
1. Our privacy commitment
Febi.ai is built on trust. Our End Users hand us their books, their records and, in many cases, personal information belonging to their own customers and employees. We treat that as a responsibility we carry rather than a formality we satisfy, and We hold ourselves to the following commitments:
We do not sell your information. Your Personal Data will not be sold, rented or traded, and We will not share it with third parties for their own marketing or advertising purposes unless you explicitly permit us to.
We collect only what We need, for reasons We have told you. We will not quietly repurpose your information for something you were not told about.
We tell you clearly what We are doing. Whenever We ask for information that identifies you, We say what it is for, in plain language, before you give it.
You stay in control. You can see what We hold, correct it, have it erased, nominate someone to act for you, and withdraw your consent — and withdrawing is as easy as giving it.
We keep it secure. We apply market-standard technical and organisational safeguards to your information, and We review them as risks change.
We do not keep information forever. When the purpose it was collected for is done, or you withdraw consent, We erase it unless the law requires us to retain it.
We stand behind the people who work for us. Where a service provider processes information on our behalf, they do so under a binding contract, and We remain answerable to you for what they do.
We tell you if something goes wrong. If your Personal Data is compromised, We will inform you and the relevant authority promptly, and explain what happened and what We are doing about it.
We take children’s privacy seriously. We do not track, profile or advertise to children, and We do not process a child’s information in any way likely to harm their well-being.
We answer when you raise a concern. Our Grievance Redressal Officer is named in this Policy with direct contact details, and We respond within the timelines the law prescribes.
These commitments bind the Company, its Affiliates, and every employee, officer, contractor and service provider acting on our behalf.
2. The principles We follow
Every decision We make about Personal Data is measured against the following principles:
Lawfulness, fairness and transparency. We process Personal Data lawfully, fairly, and transparently, on the basis of your consent or another basis expressly permitted under Applicable Law.
Purpose limitation. We collect Personal Data for specified, explicit and legitimate purposes notified to you, and do not process it further in a manner incompatible with those purposes. Use of de-identified or aggregated data for archiving in the public interest, or for research or statistical purposes, is not treated as incompatible.
Data minimisation. The Personal Data We process is adequate, relevant and limited to what is necessary for the purpose at hand.
Accuracy. We keep Personal Data accurate and, where necessary, up to date, and take every reasonable step to erase, complete or rectify data that is inaccurate, incomplete or misleading without undue delay. We are particularly careful where information will be used to make a decision affecting you or will be disclosed to another organisation.
Storage limitation. We keep Personal Data in an identifiable form only for as long as the purpose requires, or for such longer period as the law requires. Where data is retained solely for archiving, research or statistical purposes, appropriate technical and organisational protections are applied to it.
Integrity and confidentiality. We process Personal Data in a manner that ensures its security, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage.
Accountability. We accept responsibility for demonstrating that the above principles are being met, and maintain the records, contracts, training and review mechanisms described in Section 15 to prove it.
3. Definitions
“Personal Data” means any data about an individual who is identifiable by or in relation to such data.
“Data Principal” means the individual to whom the Personal Data relates, and where such individual is a child, includes their parent or lawful guardian.
“Data Fiduciary” means the Company, which alone or with others determines the purpose and means of processing Personal Data.
“Data Processor” means any entity that processes Personal Data on behalf of the Company.
“Processing” means the entire cycle of operations performed on Personal Data, including collection, recording, storage, use, sharing, and erasure.
“Consent Manager” means a person registered with the Data Protection Board of India who enables a Data Principal to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform, where applicable to our Service.
“Personal Data Breach” means any unauthorised processing of Personal Data, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to Personal Data, that compromises its confidentiality, integrity or availability.
“Sensitive Personal Data” shall have the meaning given to it under our End-User Agreement and Applicable Law.
4. What personal information do we collect, and when?
4.1 Information obtained from End Users during registration
To avail the Service, you must register with us and pay the Service Subscription Fee within the timeline set out in the End User Agreement. As part of registration, you will provide information such as your name, email address, phone number, and any other information reasonably required to register you as an End User. Once this information is shared, the Company will contact you to collect basic information about your business. You become an End User only once all such procedures are completed.
4.2 Information obtained from End Users post-registration
Once registration is complete, you will be given access to the Dashboard, onto which you will upload files (which may contain large amounts of Sensitive Personal Data) stored on and accessed through the Dashboard. You acknowledge that such sharing, storage and streamlined access is the basis of your use of Febi for bookkeeping purposes, and you grant consent to Our access, storage and usage of such shared information for that purpose. We may also automatically collect your Usage Data, IP addresses (for tracking, determining region of origin, and login/security purposes), and use Tracking Technologies to track activity on our Service. Our Service evolves over time and may introduce features that collect new or different categories of information. Where that happens, We will tell you before it affects you and, where the change is material, ask for your consent afresh.
4.3 Information from visitors
Visitors who do not register as End Users may be tracked in the same manner described above; however, information required specifically for accessing the Service will not be collected from them.
4.4 Feedback Data and Other Data
If you call our customer service, we may record information you provide, or record the call, for service delivery, quality and training purposes.
Any feedback or comments you provide to us.
4.5 Device data
We collect data about devices used to access our Service (via Website or Application), including device IP address, unique device identifiers, advertising identifiers, serial numbers, device motion data, and mobile network data.
4.6 Data collected through cookies
Cookies are data collectors on websites that typically collect information such as language and preference settings, and time spent using the Service. This information is used to analyse how you interact with our Website. You may disable cookies through your browser, though this may prevent access to certain features of the Service.
5. Notice
We will clearly inform you when information that personally identifies you (“personal information”) is being asked for, and you will have the choice to provide it or not. Generally, this information is requested when you install, download, subscribe to or register for the Service, product updates, newsletters, or other online services.
Before or at the time We collect your Personal Data, and in every request for your consent, We give you an itemised notice, in plain language, setting out:
the Personal Data being collected;
the specific purpose for which it is being collected and processed, and what that processing enables;
how you may exercise your rights, including your right to withdraw consent; and
how you may escalate a complaint to the Data Protection Board of India if We do not resolve it.
Where you gave us information before this Policy took effect, We will provide you with this notice as soon as reasonably practicable, and you may continue using the Service unless and until you withdraw your consent. Notices are available in English and, so far as reasonably practicable, in the languages specified in the Eighth Schedule to the Constitution of India.
6. Your choices and consent
Consent you give us is free, specific, informed, unconditional and unambiguous, given by clear affirmative action, and limited to the Personal Data necessary for the purpose notified to you. Where We ask you to consent to processing of Sensitive Personal Data, We identify that separately and clearly.
You may withdraw your consent at any time, and We will not make that harder than giving it was. Withdrawal does not affect the lawfulness of processing already carried out. Once you withdraw, We will stop processing your Personal Data within a reasonable time and have our Data Processors erase it, unless the law requires us to keep it. Section 13 explains how withdrawal or erasure may affect your continued use of the Service.
Where appropriate, We may work with a registered Consent Manager so you can give, manage, review and withdraw consent in one place. Any Consent Manager We use acts on your behalf and is accountable to you.
7. How do we use your information?
To operate the Service and support your use of it, including registration, responding to inquiries and requests, customer service, sending administrative information, and personalizing your experience with Febi.
To better understand our users generally and improve the content and functionality of Febi.
To communicate with you about the Service and, where you have consented, to send offers, newsletters, or marketing/promotional material relating to third-party products and services.
To personalize or customize your experience, develop new features, and improve overall Service quality; and to notify you of changes to the Service.
To run our business, including providing the Service you requested, providing support, sending notifications and reminders, and protecting the Service, including combating fraud.
To fulfil the terms of this Policy, our End User Agreement, or any other agreement We have with you.
To resolve queries, follow up on your experience, verify your identity as an End User, provide support, and detect, prevent or address technical issues. Chat transmissions with support are encrypted; please do not share more Personal Data than necessary to resolve your issue. Session transcripts may be retained for this purpose.
Feedback: Information volunteered in surveys or feedback may be combined with other customers’ responses to understand and improve the Service. Answering any survey is optional.
Research: We may combine or publish aggregated, de-identified information such that no individual End-User can be identified, including sharing such aggregated findings with third parties for research, academic, marketing or promotional purposes.
Each of these uses rests either on consent you have given us under Section 6, or on another basis expressly permitted under Applicable Law — for example, where you have voluntarily provided Personal Data for a particular purpose and have not indicated that you do not consent to its use for that purpose. We will not put your Personal Data to a new and incompatible use without first telling you and, where required, asking for your consent.
8. Do we share your personal information with third parties?
We do not sell your personal information. We do not share it with third parties for their own marketing or advertising purposes unless you explicitly permit us to do so. Where We do share Personal Data or Sensitive Personal Data with the categories of recipients below, We share only what is necessary, and only under a binding contract that requires the recipient to use it solely for the purpose We specify, keep it confidential, secure it to our standards, report any Personal Data Breach to Us promptly, and erase or return it once the purpose is served:
Affiliates and Data Processors: engaged to help us operate the Service (e.g., website design, email communications, fraud detection and prevention, customer care, analytics), bound by confidentiality and purpose-limitation obligations, and processing data only on our instructions. Where they process your information for us, We remain answerable to you for it.
Government/Legal Requests: shared with courts, law enforcement or government bodies where We have a good-faith belief this is required or permitted under Applicable Law, including for national security, or to respond to a court order, subpoena, search warrant, or law enforcement request.
Protection of the Company/Others: shared where We believe it necessary to enforce our terms of service, protect the rights, property or safety of the Company, our Service, End Users, or others, and for fraud or credit-risk protection. This does not permit selling, renting or otherwise disclosing Personal Data for commercial purposes in violation of this Policy.
Credit Bureaus: shared with credit bureaus, consumer reporting agencies and card associations, including in relation to late/missed payments, fraud, credit, or debt collection.
Related Entities: shared with our Related Entities (except where prohibited under Applicable Law) to process transactions, maintain accounts, operate our business, facilitate login/registration, offer products/services, and detect or prevent fraud.
Sale of Business: where We sell, merge, or transfer part of our business, your End User Data may be shared with the transferee, who will be required to honour this Policy in respect of the information transferred; you will be given the option to stop receiving promotional information following any change of control.
With Your Consent: for any other sharing not listed above, We will provide notice and an opportunity for you to choose.
9. Where your information is stored and processed
We may process and store your Personal Data outside India. We do not transfer Personal Data to any country or territory that the Central Government of India has restricted by notification, and We comply with any sector-specific restrictions that apply to us. Wherever your information is held, We apply contractual and technical safeguards so that it continues to receive a standard of protection consistent with this Policy and Applicable Law.
10. How do we protect your personal information?
We take reasonable security safeguards to prevent a Personal Data Breach, covering Personal Data in our possession or under our control, including data handled by our Data Processors. Access is limited to authorized employees, associates, partners and officers on a need-to-know basis, and third-party service providers are held to stringent privacy and confidentiality standards. Our physical, electronic and procedural safeguards include:
Use of specialized technology such as firewalls;
Security and operability testing of products and services before deployment, and ongoing vulnerability scanning;
Access, authentication and authorization controls across systems, including role-based access and logging of access to Personal Data;
Restrictions on use of external data devices on Company systems;
Backup and continuity measures to protect against accidental loss or destruction of information;
Training for personnel who handle Personal Data, and continual updates to our security practices as new risks emerge;
Market-standard encryption, obfuscation or tokenisation to secure Personal Data and Sensitive Personal Data, including financial data, in transit and at rest.
No method of transmission over the internet or electronic storage is completely secure, and while We use commercially reasonable efforts to protect your data, We cannot guarantee absolute security.
11. If your information is compromised
If a Personal Data Breach occurs, We will without undue delay inform you and the Data Protection Board of India in the manner prescribed, including the nature, extent, timing and location of the breach, its likely consequences, what We have done or propose to do to contain and mitigate it, and who you can contact with questions. Our Data Processors are contractually required to report any suspected or actual breach to Us immediately, and We maintain internal records of breaches and the remedial action taken.
12. Your rights
Subject to Applicable Law, you have the right to:
Access information: obtain a summary of the Personal Data We hold about you and the processing We carry out on it, including the identities of any Data Processors or other Data Fiduciaries with whom your data has been shared and the categories of data shared.
Correction and erasure: have inaccurate or misleading Personal Data corrected, incomplete data completed, data updated, and Personal Data erased once it is no longer necessary for the purpose it was collected for, unless retention is required by law.
Grievance redressal: raise a grievance with us about how your Personal Data is processed or how your rights have been handled, and receive a response within the timeline prescribed under Applicable Law.
Nominate: nominate another individual to exercise your rights on your behalf in the event of your death or incapacity.
Withdraw consent: withdraw consent you have previously given, at any time, as easily as it was given.
To exercise any of these rights, email hr@febi.ai with the request clearly identified in the subject line (for example, “REMOVE” for an erasure request). We will acknowledge your request and respond within the period prescribed under Applicable Law. Certain requests, such as deletion or withdrawal of consent, may mean you can no longer use the Service — see Section 13.
In exercising these rights, you are expected to furnish authentic information and not to raise false or frivolous grievances.
If you are not satisfied with our response, you may complain to the Data Protection Board of India.
13. Data retention and erasure
We retain your End User Data only as long as necessary to fulfil the purpose it was collected for, to operate our Service, or to meet our legal obligations, whichever is longer, whether or not you remain a current End-User. Once you withdraw consent, or once it is reasonable to assume the purpose is no longer being served, We erase your Personal Data and have our Data Processors do the same, unless the law requires us to retain it. You may request erasure by contacting us at hr@febi.ai Because Febi’s ability to deliver the Service depends on your data being stored with Us, erasing it may require us to terminate or restrict your access to the Service.
14. Children and persons with disability
Where the Service is used by or on behalf of a child, or a person with disability who has a lawful guardian, We process that Personal Data only with the verifiable consent of the parent or lawful guardian, obtained in the manner prescribed under Applicable Law. We do not track, behaviourally monitor or direct targeted advertising at children, and We do not process a child’s Personal Data in any manner likely to have a detrimental effect on their well-being.
15. How we hold ourselves accountable
The commitments in this Policy are supported by internal governance, not just by this document. We:
maintain internal data protection policies, procedures and records of our processing activities, covering the categories of Personal Data We handle, the purposes, the recipients, retention periods and safeguards;
conduct due diligence on service providers before onboarding them, and contract with them in writing on data protection, confidentiality, security, breach reporting and deletion;
train employees, contractors and other personnel who handle Personal Data, and enforce consequences for non-compliance;
review this Policy and our technical and organisational measures periodically, and whenever our Service, our processing activities or the law changes materially;
carry out internal reviews and, where warranted, independent audits and impact assessments for processing that could pose a higher risk to individuals; and
designate a responsible officer, named in Section 16, to oversee compliance, answer questions about how We process Personal Data, and run our grievance redressal mechanism.
16. Grievance Redressal Officer
If you have a grievance or a question about how your Personal Data or Sensitive Personal Data is processed, or you wish to exercise your rights, contact:
Name: Rajat Kumar
Designation: Grievance Redressal Officer
Address: 45 Arjun Marg, DLF Phase I, Gurugram
Email: Info@febi.ai
Data Protection Officer (DPO)
If you have any queries, concerns, or requests relating to the protection and processing of your Personal Data, you may contact our Data Protection Officer:
Name: Ashu Goel
Designation: Data Protection Officer
Address: 45 Arjun Marg, DLF Phase I, Gurugram
Email: dataprivacy@febi.ai
We respond to grievances within the timelines prescribed under Applicable Law.
All email messages sent to and from the Company may be monitored to ensure compliance with internal policies and to protect our business.
17. Changes to this Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, our Service, or the law. Where a change materially affects how your Personal Data is processed, We will give you notice before it takes effect and, where required, ask for your consent afresh.
18. Electronic Record
This document is an electronic record in terms of the Information Technology Act, 2000 and rules made thereunder, as applicable, and the amended provisions pertaining to electronic records in various statutes as amended by the Information Technology Act, 2000. This electronic record is generated by a computer system and does not require any physical or digital signature.